CVE-2014-4971 is a critical privilege escalation vulnerability affecting Microsoft Windows XP SP3. It stems from improper address validation in the MQAC.sys and BthPan.sys drivers, allowing local attackers to write to arbitrary memory locations. With a CVSS score of 7.2, this vulnerability is easily exploitable locally with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, multiple public exploits exist, including Metasploit modules and ExploitDB entries, indicating readily available attack tools. Community discussion, though limited, confirms awareness of this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.